Back to all articles

Small Business Cybersecurity Without an IT Department

Most small South African businesses assume real cybersecurity requires a budget and a specialist they don't have. Most of what actually matters is a handful of decisions, not a department.

Most small South African businesses assume real cybersecurity requires a budget and a specialist they don't have, so it gets pushed down the priority list indefinitely. The reality is more encouraging: most of what actually reduces risk for a small business is a handful of decisions and habits, not a department.

Start with what you'd actually lose

Before anything else, it's worth a five-minute mental exercise: if your laptop or till system vanished tomorrow, what would you actually lose — client contact details, invoicing history, a year of design work, access to your business banking? That list tells you exactly where to focus. Generic advice is less useful than protecting the three or four things that would genuinely hurt to lose.

The controls that matter most, in order

1. Separate business and personal accounts and passwords. A breach of a personal social media account shouldn't be able to cascade into business banking access. Keep them on different email addresses and different passwords, full stop.

2. Two-factor authentication on anything financial. Business banking, payment platforms, accounting software — all of it. This single control blocks the majority of account takeover attempts, even if a password leaks.

3. A password manager for the whole team. If staff share logins for shared tools, a password manager (rather than a shared note or a sticky pad) lets you revoke one person's access without resetting the password for everyone else — genuinely useful the day someone leaves.

4. Backups that are actually tested, per the ransomware guidance elsewhere on this site. For a small business, losing a year of invoicing and client records is often more damaging than any single scam.

5. A simple, written policy for payment changes. A specific and increasingly common scam: a fraudster impersonates a supplier by email, asking for banking details on an invoice to be updated. The fix isn't technical — it's a rule that any change to payment details gets confirmed by phone, using a number you already have on file, not one provided in the email.

Staff awareness, briefly

You don't need a formal training programme. What helps most is a short, recurring conversation — a five-minute chat once a quarter — about what a phishing attempt actually looks like, using a recent real example if you have one. Awareness fades quickly without repetition, so "once, at onboarding" tends not to stick.

What to skip, at least initially

Enterprise-grade security tooling, dedicated firewalls, and formal security audits are genuinely valuable at a certain size, but they're not where a five-person business gets the most protection per rand spent. The five controls above cover the overwhelming majority of realistic small-business risk, and all of them are either free or low-cost.

The honest bottom line

Cybersecurity for a small business isn't a project with an end date — it's closer to a handful of habits layered into how the business already runs. None of it requires hiring anyone. It requires making a short list of decisions once, and then simply not undoing them under time pressure later.